CVE-2017-1291

Severity
5.4MEDIUM
EPSS
0.1%
top 64.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 17

Description

IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-56cf-c44q-gv8p: IBM Maximo Asset Management 72022-05-17
CVEList
CVE-2017-1291: IBM Maximo Asset Management 72017-05-26
CVE-2017-1291 (MEDIUM CVSS 5.4) | IBM Maximo Asset Management 7.5 and | cvebase.io